Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59199.json",
"cwe_ids": [
"CWE-190",
"CWE-787"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "12.3.0"
}
],
"cpe": "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1649.0,
"function_hash": "186777945359946930939975801775170177923"
},
"id": "CVE-2026-59199-59f6cc08",
"signature_type": "Function",
"source": "https://github.com/python-pillow/pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",
"target": {
"function": "ImagingFill2",
"file": "src/libImaging/Paste.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1804.0,
"function_hash": "198802159923287429847858333651113598766"
},
"id": "CVE-2026-59199-658657f8",
"signature_type": "Function",
"source": "https://github.com/python-pillow/pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",
"target": {
"function": "ImagingPaste",
"file": "src/libImaging/Paste.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"296163850804002932414883555459713379818",
"115741992203010642505643277953344472025",
"250666387742119818199253077350116666885",
"91876094229045415556241255196288404475",
"242687451754591433859006675395045992700",
"324709129864953715865015810487018963374",
"260443116354350410193589317745027951257",
"280102789298647002004892414544689539120",
"222540834997665438075706397741234403060",
"50796734625348708066158291007582073557",
"249822155065022888012099150687071972490",
"43458357772319693472086708921802623841",
"328149464602621958290514359353666098839",
"242687451754591433859006675395045992700",
"324709129864953715865015810487018963374",
"94303673514783870225628690123372589055",
"101019720115066047389055359477221882459",
"175027921222596166709463088028731628016"
]
},
"id": "CVE-2026-59199-917115ee",
"signature_type": "Line",
"source": "https://github.com/python-pillow/pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",
"target": {
"file": "src/libImaging/Paste.c"
}
}
]
"2026-08-07T21:55:28Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59199.json"